CVE-2024-42485
12.08.2024, 16:15
Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` in the URL. Patched with Version v2.3.3.
Vendor | Product | Version |
---|---|---|
pxlrbt | filament_excel | 1.0.0 ≤ 𝑥 < 1.1.14 |
pxlrbt | filament_excel | 2.0.0 ≤ 𝑥 < 2.3.3 |
𝑥
= Vulnerable software versions